Macro.Word97.Lopez
Description Macro.Word97.Lopez
The virus replicates under MS Word ver. 8.0 only. It contains two modules Word97Virus1 and NewMacros. The "Word97Virus1" module contains eleven macros: Word97Virus1, AutoNew, AutoClose, AutoExec, AutoSave, AutoOpen, FileClose, FileNew, FileSaveAs, FilePrint, FileOpen. The virus replicates when any of these macros is activated. The "NewMacros" module contains one macro ToolsMacro that on entering the Tools/Macro menu deletes virus macros in active document and NORMAL.DOT. On printing the virus appends to the document the text: hE wHo LiVeS iN tHe PaSt HaS nO ChAnCe To SuRviVe In ThE fUtUrEall
The virus also contains the comment: Word97Virus1 Macro
Check other viruses! Be aware! Use Antiviral Software
Sister.902
Description Sister.902
It is not a dangerous nonmemory resident encrypted parasitic virus. It searches for EXE files, then writes itself to the end of the file. To locate EXE files the virus scans current and parent directories, then WINDOWSCOMMAND directory, looks for *.EXE and *.OVL files there and infects them. The virus also looks for the EDIT.COM file - it is not "true" COM file, but has EXE binary format starting from DOS 7 (Windows95). The virus checks file names and does not infect files: F-*, AV*, DR*, SC*, IV*, TB*, FI*, FV* (F-PROT, AVP, DRWEB, SCAN, etc). The virus deletes the anti-virus data files: ANTI-VIR.DAT, IVB.NTZ. It also tries to delete CHKLIST.* data files, but fails because of a bug. Depending on the system timer the virus manifests itself with a video effect and display the text: Sisters 3 close friends
The virus also contains the text strings: [Sisters] Techno Phunk/Ti
Sisters.2221
Description Sisters.2221
It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h, 16h and writes itself to the end of COM and EXE files that are executed. The virus deletes the anti-virus data files: CHKLIST.MS and CHKLIST.CPS. Depending on its internal counter and current date the virus: disables the mouse driver, erases 40 sectors on the C: drive, erases the CMOS memory, halts the computer, displays the messages: TEMPLE OF LOVE V1.0 MS 95 FoUnD VIRUS SYSTERS OF MERCY iN yOuR sYsTeM !!!
The virus INT 16h handler (keyboard) erases the CMOS memory after 700th keys entered. The virus also contains the strings: SyStEm is now halted.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Massive Athletikum Group Sklep Sportowy Datoraktuellt
|